Reflected Cross-Site Scripting Vulnerability in Citrix ADC and Citrix Gateway
CVE-2023-3466

8.3HIGH

Key Information:

Vendor
Citrix
Vendor
CVE Published:
19 July 2023

Summary

A reflected Cross-Site Scripting (XSS) vulnerability exists in Citrix ADC and Citrix Gateway, allowing an attacker to inject malicious scripts into web pages viewed by users. This flaw can be exploited to unsuspectingly execute arbitrary JavaScript code in a user's browser, potentially compromising user sessions, stealing sensitive information, or performing unauthorized actions. It is crucial for organizations using these products to apply the recommended mitigations to safeguard their applications against this vulnerability.

Affected Version(s)

NetScaler ADC  13.1 < 49.13

NetScaler ADC  13.0 < 91.13

NetScaler ADC  13.1-FIPS < 37.159

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.